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Claims 

What is claimed is: 

1. In a network, a method of processing e-mail messages 
comprising : 

a) receiving an e-mail message from an 
unknown sender ; 

b) requesting information about the sender 
from at least one database that compiles global 
statistics about senders based on information about the 
sender received from recipients in the network, wherein 
the statistics are used to determine a sender's 
reputation, wherein the sender is identified based on 
data in the message header including at least one of the 
following : 

i) an actual sender; 

ii) a final IP address used by the 

sender; 

iii) a final domain name used by the 

sender; or 

iv) an IP path used by the sender; and 

c) categorizing whether the e-mail message is 
good based on information received about the sender's 
reputation, wherein the e-mail message is allowed through 
a recipient's e-mail filter if the reputation is good and 
the e-mail message is not allowed through the e-mail 
filter if the reputation is either not good or not known. 

2 . The method of claim 1 wherein the actual sender is 
identified by a signature that includes at least two of 
the following fields from the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 
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c) 


a 


domain name used by the sender; 


d) 


a 


final IP address used by the sender; 


e) 


a 


final domain name used by the sender; 


f ) 


a 


user-agent ; 


g) 


a 


time zone ; 


h) 


a 


source IP address; 


i) 


a 


name of client software used by the 


j) 


a 


sendmail version used by a first 



receiver; and 

k) an IP path used to route the message. 



3 . The method of claim 1 wherein the actual sender is 
identified by a signature including a range of IP 
addresses and at least one of the following fields from 
the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender; 

d) the final IP address used by the sender; 

e) the final domain name used by the sender; 

f) the name of client software used by the 
actual sender; 

g) user-agent; 

h) time zone; 

i) source IP address; 

j) sendmail version used by a first receiver; 



and 



k) the IP path used to route the message. 
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4 . The method of claim 1 wherein the at least one 
database includes one of the following: 

a) a central database; or 

b) at least two centrally-maintained 
databases, each storing and compiling different 
information and statistics. 

5. The method of claim 1 further comprising using 
statistics compiled at the at least one database to 
compute a score indicating a likelihood that the received 
message is an unsolicited message. 

6. The method of claim 5 wherein the score increases as 
a number of accepted messages having the same information 
about the sender as the received message increases, the 
information including one of the following: 

a) the actual sender; 

b) a final IP address ; 

c) a final domain name; or 

d) an IP path. 

7. The method of claim 5 wherein the score decreases as 
a number of rejected messages having the same information 
about the sender as the received message increases, 

the information including one of the following: 

a) the actual sender; 

b) a final IP address; 

c) a final domain name; or 

d) an IP path. 
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8. The method of claim 1 further comprising tracking at 
least one of the following pieces of information about 
messages from senders: 

a) a total number of messages sent; 

b) a total number of messages sent over a 
first predetermined time period; 

c) a total number of messages sent to 
recipients in the network who have included the sender on 
a whitelist ; 

d) a number of messages sent to recipients in 
the network who have included the sender on the whitelist 
over a second predetermined time period; 

e) a number of recipients who have included 
the sender on the recipient's whitelist; 

f) a total number of times a recipient 
changed a sender's whitelist/blacklist status; 

g) a number of times a recipient changed a 
sender's whitelist/blacklist status over a third 
predetermined time period ,- 

h) a total number of messages sent to 
recipients in the network who have not included the 
sender on the whitelist; 

i) a number of messages sent to recipients in 
the network who have not included the sender on the 
whitelist over a fourth predetermined time period; 

j) a total number of unique recipients in the 
network who have received at least one message from the 
sender; 

k) a total number of messages sent to unique 
recipients in the network who have included the sender on 
the whitelist; and 

1) a total number of messages sent to unique 
recipients in the network who have not included the 
sender on the whitelist, 
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wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

9. The method of claim 1 wherein compiling statistics 
about senders includes at least one of the following: 

a) determining a ratio of a first number e- 
mail messages sent by a sender to recipients in the 
network who have included the sender on a whitelist in a 
predetermined time period divided by a second number of 
e-mail messages sent by the sender to users in the 
network in the predetermined time period; 

b) determining a ratio of a first number of 
recipients in the network who have included the sender on 
the whitelist divided by a second number of unique 
recipients in the network who received e-mails from the 
sender in a predetermined time period; 

c) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a whitelist to a blacklist divided 
by a second number of times a message from the sender was 
moved from a whitelist to a blacklist; 

d) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a blacklist to a whitelist divided 
by a second number of times a message from the sender was 
moved from a blacklist to a whitelist; 

e) determining a ratio of a first number of 
unique users within the network who whitelisted the 
sender within a predetermined time period compared to a 
second number of unique users within the network who 
blacklisted the sender within the predetermined time 
period; 
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f) determining a ratio reflecting whether the 
sender sends a majority of messages to recipients who 
have included the sender on the whitelist; 

g) determining a ratio reflecting a first 
number of wanted messages sent by the sender compared to 
a second number of unwanted or total messages sent by the 
sender; 

h) determining a difference between a first 
number of expected messages sent by the sender and a 
second number of unexpected messages sent by the sender; 

i) determining a difference between a first 
number of times a user whitelisted a message from the 
sender and a second number of times a user blacklisted a 
message from the sender; and 

j) determining a difference reflecting 
whether the sender sends a majority of messages to known 
recipients, 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

10. The method of claim 1 further comprising placing a 
message which is not allowed through the e-mail filter in 
a spam folder . 

11. The method of claim 10 further comprising monitoring 
the spam folder at predetermined intervals to determine 
whether messages in the folder should be released because 
the reputation of the sender has changed. 
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12 . The method of claim 1 further comprising monitoring 
the inbox at predetermined intervals to determine whether 
messages should remain in the inbox. 



13 . The method of claim 1 further comprising maintaining 
at the database at least four of the following values: 

a) a number of messages which were explicitly 
ranked good; 

b) a number of messages which were implicitly 
ranked good; 

c) a number of messages whose ranking is 

unknown ; 

d) a number of messages which were explicitly 
ranked bad; and 

e) a number of messages which were implicitly 
ranked bad; 

wherein the values are based on messages having 
the same information about the sender including one of 
the following: 

a) the signature; 

b) a final IP address used by the sender; 

c) a final domain name used by the sender; or 

d) an IP path used by the sender. 



14. The method of claim 13 wherein the values represent 
one of the following: 

a) message counts; or 

b) ratings of unique users within the 

network . 
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15. The method of claim 14 further comprising at least 
four of the values being returned to the recipient to 
allow the recipient to apply different weights to a 
message in order to categorize the message. 

16. The method of claim 1 further comprising tracking 
local statistics about senders identified by data in the 
message header at a local database . 

17. The method of claim 1 further comprising assessing 
the reputation of the sender of a received message when 
user activity is observed. 

18. The method of claim 1 further comprising sending 
recipients a notification when any sender's reputation 
changes . 

19. The method of claim 18 further comprising reviewing 
all messages received in a predetermined time period 
preceding receipt of the notification and updating the 
categorization of the message as necessary. 

20. In a network, a method of processing e-mail messages 
comprising : 

a) receiving information about e-mail 
messages from recipients of the messages in the network, 
wherein the information received includes: 

i) an identification of a sender of a 
first message, wherein the identification is based on 
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data in the message header and includes at least one of 
the following : 

A) an actual sender; 

B) a final IP address used by the 



sender; 
sender; or 
and 



C) a final domain name used by the 

D) an IP path used by the sender; 



ii) an indication of whether the 
recipient considered the first message good or bad; 

b) compiling global statistics for senders of 
messages , wherein the statistics are used to determine a 
sender's reputation for sending good messages; and 

c) creating a list of senders with good 
reputations that may be referenced by recipients of 
messages from unknown senders in the network, wherein a 
second message from one sender on the list is allowed 
through a recipient's e-mail filter and a third message 
from another sender not on the list is not allowed 
through the recipient's e-mail filter . 



21. The method of claim 20 wherein the actual sender is 
identified by a signature having at least two of the 
following fields from the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender; 

d) a final IP address used by the sender; 

e) a final domain name used by the sender; 

f) a user-agent; 

g) a time zone; 

h) a source IP address; 
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i) a name of client software used by the 

sender; 

j) a sendmail version used by a first 
receiver; and 

k) an IP path used to route the message. 



22. The method of claim 21 wherein the actual sender is 
identified by a signature including a range of IP 
addresses and at least one of the following fields from 
the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender; 

d) the final IP address used by the sender; 

e) the final domain name used by the sender ; 

f) the name of client software used by the 



actual sender ; 

g) user-agent; 



and 



h) time zone; 

i) source IP address; 

j) sendmail version used by a first receiver; 

k) the IP path used to route the message. 



23. The method of claim 20 wherein the at least one 
database includes one of the following: 

a) a central database; or 

b) at least two centrally-maintained 
databases, each storing and compiling different 
information and statistics. 
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24. The method of claim 20 further comprising using 
statistics compiled at the at least one database to 
determine a sender's reputation. 

25. The method of claim 24 further comprising adding a 
sender to the list when the sender's reputation passes a 
predetermined threshold indicating a good reputation. 

26. The method of claim 24 further comprising removing a 
sender from the list when the sender's reputation is 
below a predetermined threshold indicating a good 
reputation. 

27. The method of claim 20 further comprising tracking 
at least one of the following pieces of information about 
messages from senders: 

a) a total number of messages sent; 

b) a total number of messages sent over a 
first predetermined time period; 

c) a total number of messages sent to 
recipients in the network who have included the sender on 
a whitelist; 

d) a number of messages sent to recipients in 
the network who have included the sender on the whitelist 
over a second predetermined time period; 

e) a number of recipients who have included 
the sender on the recipient's whitelist; 

f) a total number of times a recipient 
changed a sender's whitelist/blacklist status; 

g) a number of times a recipient changed a 
sender's whitelist/blacklist status over a third 
predetermined time period; 
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h) a total number of messages sent to 
recipients in the network who have not included the 
sender on the whitelist; 

i) a number of messages sent to recipients in 
the network who have not included the sender on the 
whitelist over a fourth predetermined time period; 

j ) a total number of unique recipients in the 
network who have received at least one message from the 
sender; 

k) a total number of messages sent to unique 
recipients in the network who have included the sender on 
the whitelist; and 

1) a total number of messages sent to unique 
recipients in the network who have not included the 
sender on the whitelist', 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

28. The method of claim 20 wherein compiling statistics 
about senders includes at least one of the following: 

a) determining a ratio of a first number e- 
mail messages sent by a sender to recipients in the 
network who have included the sender on a whitelist in a 
predetermined time period divided by a second number of 
e-mail messages sent by the sender to users in the 
network in the predetermined time period; 

b) determining a ratio of a first number of 
recipients in the network who have included the sender on 
the whitelist divided by a second number of unique 
recipients in the network who received e-mails from the 
sender in a predetermined time period; 
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c) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a whitelist to a blacklist divided 
by a second number of times a message from the sender was 
moved from a whitelist to a blacklist; 

d) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a blacklist to a whitelist divided 
by a second number of times a message from the sender was 
moved from a blacklist to a whitelist; 

e) determining a ratio of a first number of 
unique users within the network who whitelisted the 
sender within a predetermined time period compared to a 
second number of unique users within the network who 
blacklisted the sender within the predetermined time 
period; 

f) determining a ratio reflecting whether the 
sender sends a majority of messages to recipients who 
have included the sender on the whitelist; 

g) determining a ratio reflecting a first 
number of wanted messages sent by the sender compared to 
a second number of unwanted or total messages sent by the 
sender ; 

h) determining a difference between a first 
number of expected messages sent by the sender and a 
second number of unexpected messages sent by the sender; 

i) determining a difference between a first 
number of times a user whitelisted a message from the 
sender and a second number of times a user blacklisted a 
message from the sender; and 

j) determining a difference reflecting 
whether the sender sends a majority of messages to known 
recipients , 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
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address, the final domain name, or the IP path used to 
send the message. 

29. The method of claim 20 further comprising placing a 
message which is not allowed through the e-mail filter in 
a spam folder. 



30. The method of claim 29 further comprising monitoring 
the spam folder at predetermined intervals to determine 
whether messages in the folder should be released because 
the reputation of the sender has changed. 



31. The method of claim 20 further comprising monitoring 
the inbox at predetermined intervals to determine whether 
messages should remain in the inbox. 



32. The method of claim 20 further comprising 
maintaining at the database at least four of the 
following values: 

a) a number of messages which were explicitly 
ranked good; 

b) a number of messages which were implicitly- 
ranked good; 

c) a number of messages whose ranking is 

unknown ; 

d) a number of messages which were explicitly- 
ranked bad; and 

e) a number of messages which were implicitly 
ranked bad; 
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wherein the values are based on messages having 
the same information about the sender including one of 
the following: 

a) the signature; 

b) a final IP address used by the sender; 

c) a final domain name used by the sender; or 

d) an IP path used by the sender. 

33. The method of claim 32 wherein the values represent 
one of the following: 

a) message counts; or 

b) ratings of unique users within the 

network . 

34. The method of claim 20 further comprising tracking 
local statistics about senders identified by data in the 
message header at a local database. 

35. The method of claim 20 further comprising assessing 
the reputation of the sender of a received message when 
user activity is observed. 

36. The method of claim 20 further comprising sending 
recipients a notification when any sender's reputation 
changes . 

37. The method of claim 20 further comprising reviewing 
all messages received in a predetermined time period 
preceding receipt of the notification and updating the 
categorization of the message as necessary. 
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38. In a network, a system for processing e-mail 
messages comprising : 

a) a plurality of senders of e-mail messages; 

b) a plurality of recipients of e-mail 
messages in network connection with the plurality of 
senders, each of the recipients having a first software 
means for filtering received e-mail messages; 

c) at least one database in network 
connection with the plurality of recipients, the database 
having second software means for performing the 
following : 

i) receiving information about e-mail 
messages from the recipients of the messages, wherein the 
information received includes: 

A) an identification of a sender of 
a first message based on data in the message header 
including at least one of the following: 

I) an actual sender; 

II) a final IP address used by 

the sender; 

III) a final domain name used by 

the sender; or 

IV) an IP path used by the 

sender; and 

B) an indication of whether the 
recipient considered the first message good or bad; 

ii) compiling statistics for senders of 
messages, wherein the statistics are used to determine a 
sender's reputation for sending good messages; and 

iii) sending statistics in response to a 
request for statistics from the recipient of a message 
from an unknown sender, wherein if the sender has a good 
reputation the message is allowed through the first 
software means and if the sender has a not good or not 
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known reputation the message is not allowed through the 
first software means. 

39. The system of claim 38 wherein the at least one 
database includes one of the following: 

a) a central database; or 

b) at least two centrally-maintained 
databases, each storing and compiling different 
information and statistics. 

40. The system of claim 38 wherein the at least one 
database and the plurality of recipients are members of 
an e-mail network. 

41. The system of claim 38 further comprising an 
incoming mail server in network connection with each of 
the plurality of recipients. 

42. The system of claim 38 wherein the actual sender is 
identified by signature including at least two of the 
following fields from the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender ; 

d) a final IP address used by the sender; 

e) a final domain name used by the sender; 

f) a user-agent; 

g) a time zone; 

h) a source IP address; 

i) a name of client software used by the 

sender; 
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j) a sendmail version used by a first 
receiver; and 

k) an IP path used to route the message. 



43. The system of claim 38 wherein the actual sender is 
identified by a signature including a range of IP 
addresses and at least one of the following fields from 
the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender; 

d) the final IP address used by the sender; 

e) the final domain name used by the sender; 

f) the name of client software used by the 
actual sender; 

g) user-agent; 

h) timezone ; 

i) source IP address; 

j) sendmail version used by a first receiver; 



and 



k) the IP path used to route the message. 



44. The system of claim 38 further comprising either the 
first or second software means using statistics compiled 
at the at least one database to compute a score 
indicating a likelihood that the received message is an 
unsolicited message. 
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45. The system of claim 44 wherein the score increases 
as a number of accepted messages having the same 
information about the sender as the received message 
increases, the information including one of the 
following : 

a) the actual sender; 

b) a final IP address; 

c) a final domain name; or 

d) an IP path. 

46. The system of claim 44 wherein the score decreases 
as a number of rejected messages having the same 
information about the sender as the received message 
increases, the information including one of the 
following : 

a) the actual sender; 

b) a final IP address; 

c) a final domain name; or 

d) an IP path. 

47. The system of claim 38 further comprising the second 
software means tracking at least one of the following 
pieces of information about messages from senders: 

a) a total number of messages sent; 

b) a total number of messages sent over a 
first predetermined time period; 

c) a total number of messages sent to 
recipients in the network who have included the sender on 
a whitelist; 

d) a number of messages sent to recipients in 
the network who have included the sender on the whitelist 
over a second predetermined time period; 
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e) a number of recipients who have included 
the sender on the recipient's whitelist; 

f) a total number of times a recipient 
changed a sender's whitelist/blacklist status; 

g) a number of times a recipient changed a 
sender's whitelist/blacklist status over a third 
predetermined time period; 

h) a total number of messages sent to 
recipients in the network who have not included the 
sender on the whitelist; 

i) a number of messages sent to recipients in 
the network who have not included the sender on the 
whitelist over a fourth predetermined time period; 

j) a total number of unique recipients in the 
network who have received at least one message from the 
sender; 

k) a total number of messages sent to unique 
recipients in the network who have included the sender on 
the whitelist; and 

1) a total number of messages sent to unique 
recipients in the network who have not included the 
sender on the whitelist, 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

48. The system of claim 38 wherein compiling statistics 
about senders includes at least one of the following: 

a) determining a ratio of a first number e- 
mail messages sent by a sender to recipients in the 
network who have included the sender on a whitelist in a 
predetermined time period divided by a second number of 
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e-mail messages sent by the sender to users in the 
network in the predetermined time period; 

b) determining a ratio of a first number of 
recipients in the network who have included the sender on 
the whitelist divided by a second number of unique 
recipients in the network who received e-mails from the 
sender in a predetermined time period; 

c) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a whitelist to a blacklist divided 
by a second number of times a message from the sender was 
moved from a whitelist to a blacklist; 

d) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a blacklist to a whitelist divided 
by a second number of times a message from the sender was 
moved from a blacklist to a whitelist; 

e) determining a ratio of a first number of 
unique users within the network who whitelisted the 
sender within a predetermined time period compared to a 
second number of unique users within the network who 
blacklisted the sender within the predetermined time 
period; 

f) determining a ratio reflecting whether the 
sender sends a majority of messages to recipients who 
have included the sender on the whitelist; 

g) determining a ratio reflecting a first 
number of wanted messages sent by the sender compared to 
a second number of unwanted or total messages sent by the 
sender; 

h) determining a difference between a first 
number of expected messages sent by the sender and a 
second number of unexpected messages sent by the sender; 
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i) determining a difference between a first 
number of times a user whitelisted a message from the 
sender and a second number of times a user blacklisted a 
message from the sender; and 

j) determining a difference reflecting 
whether the sender sends a majority of messages to known 
recipients , 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

49. The system of claim 38 further comprising the first 
software means placing a message which is not allowed 
through the e-mail filter in a spam folder. 

50. The system of claim 49 further comprising the second 
software means monitoring the spam folder at 
predetermined intervals to determine whether messages in 
the folder should be released because the reputation of 
the sender has changed. 

51. The system of claim 50 further comprising the second 
software means monitoring the inbox at predetermined 
intervals to determine whether messages should remain in 
the inbox. 
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52. The system of claim 38 further comprising the second 
software means maintaining at the database at least four 
of the following values: 

a) a number of messages which were explicitly 
ranked good; 

b) a number of messages which were implicitly 
ranked good; 

c) a number of messages whose ranking is 

unknown ; 

d) a number of messages which were explicitly 
ranked bad; and 

e) a number of messages which were implicitly 
ranked bad; 

wherein the values are based on messages having 
the same information about the sender including one of 
the following: 

a) the actual sender; 

b) a final IP address used by the sender; 

c) a final domain name used by the sender; or 

d) an IP path used by the sender. 



53 . The system of claim 52 wherein the values represent 
one of the following: 

a) message counts; or 

b) ratings of unique users within the 

network . 



54 . The system of claim 53 further comprising the second 
software means returning at least four of the values 
being to the recipient to allow the recipient to apply 
different weights to a message in order to categorize the 
message . 
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55. The system of claim 38 further comprising a third 
software means tracking local statistics about senders 
identified by data in the message header at a local 
database . 

56. The system of claim 38 further comprising the second 
software means assessing the reputation of the sender of 
a received message when user activity is observed. 

57. The system of claim 38 further comprising the second 
software means sending recipients a notification when any 
sender's reputation changes. 

58. The system of claim 57 further comprising the first 
software means reviewing all messages received in a 
predetermined time period preceding receipt of the 
notification and updating the categorization of the 
message as necessary . 

59. In a network, a system for processing e-mail 
messages comprising : 

a) a plurality of senders of e-mail messages; 

b) a plurality of recipients of e-mail 
messages in network connection with the plurality of 
senders, each of the recipients having a first software 
means for filtering received e-mail messages; 

c) a database in network connection with the 
plurality of recipients, the database having a second 
software means for performing the following: 
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i) receiving information about e-mail 
messages from the recipients of the messages, wherein the 
information received includes: 

A) an identification of a sender of 
a first message based on data in the message header 
including at least one of the following: 

I) an actual sender; 

II) a final IP address used by 

the sender; 

III) a final domain name used by 

the sender ; or 

IV) an IP path used by the 

sender; and 

B) an indication of whether the 
recipient considered the first message good or bad; 

ii) compiling statistics for senders of 
messages, wherein the statistics are used to determine a 
sender's reputation for sending good messages; and 

iii) creating a list of senders with good 
reputations that may be referenced by recipients of 
messages from unknown senders in the network, wherein a 
second message from one sender on the list is allowed 
through the recipient's first software means for 
filtering received messages and a third message from 
another sender not on the list is not allowed through the 
recipient's first software means for filtering received 
messages . 

60. The system of claim 59 wherein the at least one 
database includes one of the following: 

a) a central database; or 

b) at least two centrally-maintained 
databases, each storing and compiling different 
information and statistics . 
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61. The system of claim 59 wherein the at least one 
database and the plurality of recipients are members of 
an e-mail network. 

62. The system of claim 59 further comprising an 
incoming mail server in network connection with each of 
the plurality of recipients. 

63. The system of claim 59 wherein the actual sender is 
identified by a signature having at least two of the 
following fields from the message header: 



a) 


an e-mail address used by the sender; 


b) 


a 


display name used by the sender; 


c) 


a 


domain name used by the sender; 


d) 


a 


final IP address used by the sender; 


e) 


a 


final domain name used by the sender; 


f) 


a 


user-agent ; 


g) 


a 


time zone ; 


h) 


a 


source IP address ; 


i) 


a 


name of client software used by the 


j) 


a 


sendmail version used by a first 



receiver; and 

k) an IP path used to route the message. 

64. The system of claim 59 wherein the actual sender is 
identified by a signature including a range of IP 
addresses and at least one of the following fields from 
the message header: 

a) an e-mail address used by the sender; 

b) a display name used by the sender; 

c) a domain name used by the sender ; 
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d) the final IP address used by the sender; 

e) the final domain name used by the sender; 

f) the name of client software used by the 
actual sender; 

g) user-agent ; 

h) timezone; 

i) source IP address; 

j) sendmail version used by a first receiver; 

and 

k) the IP path used to route the message. 



65. The system of claim 59 further comprising the second 
software means using statistics compiled at the at least 
one database to determine a sender's reputation. 



66. The system of claim 65 further comprising adding a 
sender to the list when the sender's reputation passes a 
predetermined threshold indicating a good reputation. 



67. The system of claim 65 further comprising removing a 
sender from the list when the sender' s reputation is 
below a predetermined threshold indicating a good 
reputation . 



68. The system of claim 59 further comprising the second 
software means tracking at least one of the following 
pieces of information about messages from senders: 

a) a total number of messages sent; 

b) a total number of messages sent over a 
first predetermined time period; 
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c) a total number of messages sent to 
recipients in the network who have included the sender on 
a whitelist; 

d) a number of messages sent to recipients in 
the network who have included the sender on the whitelist 
over a second predetermined time period; 

e) a number of recipients who have included 
the sender on the recipient's whitelist; 

f) a total number of times a recipient 
changed a sender's whitelist/blacklist status; 

g) a number of times a recipient changed a 
sender's whitelist/blacklist status over a third 
predetermined time period; 

h) a total number of messages sent to 
recipients in the network who have not included the 
sender on the whitelist; 

i) a number of messages sent to recipients in 
the network who have not included the sender on the 
whitelist over a fourth predetermined time period; 

j) a total number of unique recipients in the 
network who have received at least one message from the 
sender; 

k) a total number of messages sent to unique 
recipients in the network who have included the sender on 
the whitelist; and 

1) a total number of messages sent to unique 
recipients in the network who have not included the 
sender on the whitelist, 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message . 
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69. The system of claim 59 wherein compiling statistics 
about senders includes at least one of the following: 

a) determining a ratio of a first number e- 
mail messages sent by a sender to recipients in the 
network who have included the sender on a whitelist in a 
predetermined time period divided by a second number of 
e-mail messages sent by the sender to users in the 
network in the predetermined time period; 

b) determining a ratio of a first number of 
recipients in the network who have included the sender on 
the whitelist divided by a second number of unique 
recipients in the network who received e-mails from the 
sender in a predetermined time period; 

c) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a whitelist to a blacklist divided 
by a second number of times a message from the sender was 
moved from a whitelist to a blacklist; 

d) determining a ratio of a first number of 
times in a predetermined time interval a message from the 
sender was moved from a blacklist to a whitelist divided 
by a second number of times a message from the sender was 
moved from a blacklist to a whitelist; 

e) determining a ratio of a first number of 
unique users within the network who whitelisted the 
sender within a predetermined time period compared to a 
second number of unique users within the network who 
blacklisted the sender within the predetermined time 
period; 

f) determining a ratio reflecting whether the 
sender sends a majority of messages to recipients who 
have included the sender on the whitelist; 

g) determining a ratio reflecting a first 
number of wanted messages sent by the sender compared to 



P6: PRO- 018 .CLS 



-70- 



a second number of unwanted or total messages sent by the 
sender; 

h) determining a difference between a first 
number of expected messages sent by the sender and a 
second number of unexpected messages sent by the sender; 

i) determining a difference between a first 
number of times a user whitelisted a message from the 
sender and a second number of times a user blacklisted a 
message from the sender; and 

j) determining a difference reflecting 
whether the sender sends a majority of messages to known 
recipients , 

wherein the sender is identified by one of the 
group consisting of the actual sender, the final IP 
address, the final domain name, or the IP path used to 
send the message. 

70. The system of claim 59 further comprising the first 
software means placing a message which is not allowed 
through the e-mail filter in a spam folder. 

71. The system of claim 70 further comprising the second 
software means monitoring the spam folder at 
predetermined intervals to determine whether messages in 
the folder should be released because the reputation of 
the sender has changed. 

72. The system of claim 59 further comprising the second 
software means monitoring the inbox at predetermined 
intervals to determine whether messages should remain in 
the inbox. 
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73. The system of claim 59 further comprising the second 
software means maintaining at the database at least four 
of the following values: 

a) a number of messages which were explicitly 
ranked good; 

b) a number of messages which were implicitly 
ranked good; 

c) a number of messages whose ranking is 

unknown ; 

d) a number of messages which were explicitly 
ranked bad; and 

e) a number of messages which were implicitly 
ranked bad; 

wherein the values are based on messages having 
the same information about the sender including one of 
the following: 

a) the signature; 

b) a final IP address used by the sender; 

c) a final domain name used by the sender; or 

d) an IP path used by the sender. 



74 . The system of claim 73 wherein the values represent 
one of the following: 

a) message counts; or 

b) ratings of unique users within the 

network . 



75. The system of claim 59 further comprising a third 
software means tracking local statistics about senders 
identified by data in the message header at a local 
database . 
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76. The system of claim 59 further comprising the second 
software means assessing the reputation of the sender of 
a received message when user activity is observed. 

77. The system of claim 59 further comprising the second 
software means sending recipients a notification when any 
sender's reputation changes. 

78. The system of claim 77 further comprising the first 
software means reviewing all messages received in a 
predetermined time period preceding receipt of the 
notification and updating the categorization of the 
message as necessary . 
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